Best Detection of 2026 Series: DNS-Based ClickFix Variant Using nslookup for Payload Staging
Detects a ClickFix-style activity where an adversary uses nslookup.exe or certutil.exe to perform DNS TXT record queries for payload staging or C2 rendezvous. The rule identifies suspicious parent processes like explorer.exe or scripting hosts, correlates this with a subsequent outbound network connection from the same host, and is intended to capture DNS-based beaconing or data staging.
Splunk (SPL)

